diff --git a/ai/llmstxt.mdx b/ai/llmstxt.mdx index d964b4cce..95a9d1ccc 100644 --- a/ai/llmstxt.mdx +++ b/ai/llmstxt.mdx @@ -26,7 +26,7 @@ View your `llms.txt` by appending `/llms.txt` to your documentation site's URL. Mintlify adds HTTP headers to every response, including [Markdown responses](/ai/markdown-export) and 404 pages, so AI tools can discover your `llms.txt` files and other agent resources without prior knowledge of their location: -- `Link`: Follows the standard HTTP `Link` header format for resource discovery. Advertises `llms.txt`, `llms-full.txt`, your API catalog, [MCP server card](/ai/model-context-protocol#discovery-endpoint), [agent card](/ai/skillmd#agent-card), and [agent skills index](/ai/skillmd#skills-discovery-endpoints). +- `Link`: Follows the standard HTTP `Link` header format for resource discovery. Advertises `llms.txt`, `llms-full.txt`, your [API catalog](/api-playground/openapi-setup#let-visitors-download-your-spec) (served only when you enable `download-spec`), [MCP server card](/ai/model-context-protocol#discovery-endpoint), [agent card](/ai/skillmd#agent-card), and [agent skills index](/ai/skillmd#skills-discovery-endpoints). - `X-Llms-Txt`: A convenience header for tools that check for `llms.txt` support. ```http Response headers diff --git a/api-playground/openapi-setup.mdx b/api-playground/openapi-setup.mdx index a1978a6f9..02fe5b81e 100644 --- a/api-playground/openapi-setup.mdx +++ b/api-playground/openapi-setup.mdx @@ -306,6 +306,8 @@ Opt into a "Download API spec" entry in the [page context menu](/organize/settin When enabled, clicking the option downloads your OpenAPI spec directly. Projects with multiple specs receive them bundled as `api-specs.zip`. On projects behind `auth` or `userAuth`, only authenticated readers can download the spec. +Enabling `download-spec` also publishes an [RFC 9727](https://www.rfc-editor.org/rfc/rfc9727) API catalog at `/.well-known/api-catalog`. The catalog links to each OpenAPI spec in your `docs.json` so AI agents can discover your API without crawling your docs. Without `download-spec`, `/.well-known/api-catalog` returns a 404. On projects behind `auth` or `userAuth`, only authenticated readers can access the catalog. + The downloaded OpenAPI spec is unfiltered and does not respect [authentication groups](/deploy/authentication-setup). Any authenticated reader who can open the contextual menu receives the full spec, including endpoints and schemas that would otherwise be hidden from their group. Do not enable `download-spec` on an authenticated site if your OpenAPI spec contains endpoints or fields you consider sensitive. diff --git a/help-center/register-external-mcp-server-in-discovery.mdx b/help-center/register-external-mcp-server-in-discovery.mdx index 472bb6437..613803c10 100644 --- a/help-center/register-external-mcp-server-in-discovery.mdx +++ b/help-center/register-external-mcp-server-in-discovery.mdx @@ -6,7 +6,7 @@ keywords: ["MCP discovery", "external MCP server", "well-known mcp", "second MCP Mintlify hosts a search MCP server for every site and advertises it through the `/.well-known/mcp`, `/.well-known/mcp.json`, `/.well-known/mcp/server-card.json`, and `/.well-known/mcp/server-cards.json` endpoints described in [Search MCP server](/ai/model-context-protocol#discovery-endpoint). These endpoints are generated automatically and only list the MCP servers Mintlify hosts for your site (the public `/mcp` endpoint, and `/authed/mcp` if you use authentication). There is no `docs.json` field for adding a second, externally hosted MCP server to those responses. -The same applies to the `/.well-known/api-catalog` endpoint that Mintlify advertises through the [agent `Link` header](/ai/llmstxt#link-header): that catalog lists OpenAPI documents ingested from your `docs.json`, not MCP servers. +The same applies to the `/.well-known/api-catalog` endpoint that Mintlify advertises through the [agent `Link` header](/ai/llmstxt#link-header): that catalog lists OpenAPI documents ingested from your `docs.json`, not MCP servers. The catalog is only served when you [opt into spec downloads](/api-playground/openapi-setup#let-visitors-download-your-spec). If you run your own MCP server outside Mintlify and want it discoverable alongside the built-in one on your docs domain, use one of the options below.